CodeWhale Bot 5f5ec5d147 feat(sandbox): bwrap container essentials + configurable extra roots (#5410)
The bwrap sandbox ran with a bare read-only root bind, so 'foo >/dev/null'
failed with EROFS (the host node under a read-only bind rejects
open(O_WRONLY)) and toolchains expecting /proc or writable /tmp broke —
the #5410 report. Give the invocation the standard container trio:
--dev /dev (fresh private device nodes, redirection works), --proc /proc,
--tmpfs /tmp (writable-but-isolated scratch).

Add the two requested config keys as escape hatches: bwrap_ro_roots
(extra read-only binds, applied last so they can narrow policy-writable
paths) and bwrap_dev_roots (host device nodes bind-mounted read-write;
character/block devices only — never directories — so the key cannot
become a writable-root escape hatch). Non-existent paths skip silently,
same rule as writable roots.

Threaded: config.rs (serde + profile merge), EngineConfig.bwrap_extensions,
SandboxManager.set_bwrap_extensions (+ ShellManager passthrough), engine +
runtime_threads + frame.rs constructors, config.example.toml docs.

Tests (linux-gated, CI ubuntu leg): container trio present; extensions add
ro/dev mounts, skip missing + non-device entries; extension ro-binds apply
after writable binds so narrowing wins. Off-Linux, resolve() is a no-op.

(cherry picked from commit 04239a8f3c)
2026-08-16 21:58:21 -07:00
2026-08-08 19:59:20 -07:00
2026-06-25 11:41:18 +08:00

Codewhale

An open source coding agent for your terminal — bring your own model.

Codewhale started as a native experience for DeepSeek. It has since grown into a community-driven project: one coding harness that fits a growing international community and supports as many models and providers as possible — open models first, hosted or local, none privileged over the rest.

Give it a provider, a model, and a task. It reads your code, edits files, runs commands, and checks its own work, then stops when the job is done or it needs you. Switch models mid-task with /model. Work interactively in the TUI, or run codewhale exec in scripts and CI. It's written in Rust, licensed MIT, and runs on your machine.

The part that isn't like other harnesses: you pick the model for each role, and they don't have to match. A fleet pins a provider, a model, and a reasoning tier per role — so a cheap fast model can direct an expensive reasoning one, or a GLM builder can work the same job as a Kimi reviewer. Write your own roles, your own constitution, and the harness is yours rather than ours.

We're always looking for contributors and ways to improve. If a model or provider you use is missing, or something breaks, telling us is one of the most useful things you can do — see Contributing.

简体中文 · 日本語 · Tiếng Việt · Bahasa Indonesia · 한국어 · Español · Português · Русский · Українська · Français · Deutsch · 繁體中文 · हिन्दी · Türkçe · Italiano · Polski · العربية · Català · codewhale.net · Docs · Changelog · Discord

CI crates.io npm Discord

Codewhale running in a terminal

Install

npm install -g codewhale

Cargo, Docker, Nix, Scoop, prebuilt archives, Android/Termux, and a CNB mirror for anyone who can't reach GitHub are covered in docs/INSTALL.md. Coming from deepseek-tui? Your config and sessions carry over — see docs/REBRAND.md.

Use

codewhale auth set --provider deepseek   # or export ANTHROPIC_API_KEY, etc.
codewhale                                # open the TUI
codewhale exec "fix the failing test"    # headless
codewhale web                            # local browser client on 127.0.0.1

In the TUI: /model switches provider and model together, /fleet builds and runs the team — one role at a time, each with its own model — /undo reverts the last turn, and /restore <N> rolls the workspace back to an earlier snapshot (bare /restore lists them). Tab cycles Plan / Work / Operate when the composer is empty — with text in it, Tab completes slash commands and @ mentions instead. Shift+Tab cycles the Ask / Auto-Review / Full Access permission posture at any time. ! runs a shell command through the normal approval path.

What it does

  • Any model, any provider — and any mix of them. DeepSeek, Claude, GPT, Kimi, GLM, and 30+ providers, plus your own vLLM, SGLang, or Ollama with no key, all through one runtime and one toolset. The catalog tracks each provider's live lineup — DeepSeek's V4 Pro backend (labeled DeepSeek-V4-Pro-0813) stays callable as deepseek-v4-pro, Grok 4.6 is the direct xAI default, and OrcaRouter routes through orcarouter/auto. A saved role records its provider, model, and reasoning tier explicitly, so a fleet can span vendors in a single run and a role's route never depends on whichever provider happens to be active. Context limits and prices come from the real route, and an unknown price shows as unknown rather than $0.
  • A harness you author. Roles are files you can read and edit — a model, a tool posture, and standing instructions per role — kept in the project so the team shares them, or beside your other personal settings so they follow you between repos. A constitution records how you want the agent to behave across every session, so the harness matches your practice instead of ours.
  • Read-only until you allow more. Plan mode can't change files, and approvals gate risky commands. When an OS sandbox actually wraps a command, Codewhale says so: Seatbelt on macOS where available, opt-in bubblewrap on Linux. A repo's constitution.json compiles into write holds that even Full Access can't skip.
  • Work you can resume. A fleet records every step to an append-only ledger, so fleet resume picks up where you left off.

Integrations

  • DeepSeek Harness (dsh) — connected through Codewhale. codewhale integrations dsh connect links an existing @deepseek-ai/dsh install to your Codewhale provider route, permissions, and workspace, and integrations dsh install-bundle adds the opt-in DSH plugin bundle so dsh --profile codewhale carries that identity on its own. Codewhale owns permissions and lifecycle authority; dsh keeps its own sessions, profiles, and credentials untouched. See docs/INTEGRATIONS_DSH.md.
  • VS Code. The official extension scaffold (extensions/vscode) opens Codewhale in an integrated terminal and exposes a read-only Agent View over the local runtime. It is a local-development preview, not a marketplace release yet.

Learn more

Everything else — modes, keybindings, sandbox details, MCP, the runtime API, and architecture — lives in docs and on codewhale.net.

Contributing

Issues, PRs, repro steps, logs, and feature requests are all real project work, and first contributions are welcome. When a PR can't merge as-is, maintainers harvest what works and keep the author credited — in the commit, the changelog, and docs/CONTRIBUTORS.md.

Thanks to DeepSeek for the models and support that started the project, DataWhale 🐋 for welcoming us into the Whale Brother family, and OpenWarp and Open Design for collaborating on the terminal-agent experience.

License

MIT. An independent community project, not affiliated with any model provider.

Codewhale fanning out three read-only scout subagents in a terminal

Description
面向 DeepSeek V4 的终端原生编程智能体:100 万 token 上下文、思考模式流式推理、前缀缓存感知。自包含 Rust 二进制发布——开箱即带 MCP 客户端、沙箱和持久化任务队列
Readme MIT 378 MiB
Languages
Rust 92.9%
TypeScript 3.2%
JavaScript 1.7%
Python 1%
Shell 0.7%
Other 0.3%